Skip to content

Archive

Networking

79 articles
Linux 16 Sep 2026 5 min read

Linux TCP TIME_WAIT Retains Closed Connection State

A TCP socket can disappear from an application while the kernel still retains state for the closed connection. On Linux, the endpoint that completes the active close commonly enters TIME_WAIT, keeping enough protocol state to protect a later connection from delayed segments associated with the old one. This state is not evidence that a process forgot to close a file descriptor. The application-visible socket can already be gone. TIME_WAIT belongs to TCP’s connection-lifecycle machinery and persists independently of the process that initiated the close.

Linux 16 Sep 2026 4 min read

Linux TCP Autocorking Coalesces Consecutive Small Writes

A small TCP write does not always trigger an immediate packet transmission on Linux. With TCP autocorking enabled, the stack can defer a new small send when an earlier packet from the same flow is still waiting in a qdisc or device transmit queue, giving a following write a chance to join the pending data. The mechanism targets packet count rather than application-visible buffering semantics. A successful write() or sendmsg() still reports bytes accepted by the socket; autocorking influences when queued bytes advance into transmission.

Tech 16 Sep 2026 7 min read

Jumbo Frames Raise Payload Efficiency and MTU Risk

Ethernet networks commonly use an IP maximum transmission unit of 1500 bytes, but many switches, network adapters, and operating systems also support larger frames often called jumbo frames. A larger MTU lets each packet carry more application data before another set of packet headers and per-packet processing is required. That can reduce packet rate for a given throughput. The benefit is most relevant when hosts move large volumes of data and the full path supports the selected frame size.

Software Engineering 16 Sep 2026 7 min read

HTTP 421 Misdirected Request Marks a Connection Authority Boundary

An HTTP/2 client can reuse one secured connection for requests to more than one origin when the server is authoritative for those origins. A request can still reach a server instance whose connection context does not fit the target URI. 421 Misdirected Request exists for that boundary: the server rejects the routing context rather than treating the target resource itself as missing. This distinction separates resource semantics from connection authority. A 421 response says that this server, on this path or connection context, is unable or unwilling to produce an authoritative response for the target URI. It does not say that the resource has been deleted, that its method is forbidden, or that the request representation is invalid.

Tech 16 Sep 2026 6 min read

Ethernet Pause Frames Temporarily Stop Link Transmission

Ethernet links can move frames faster than a receiving device can process or forward them. When that mismatch lasts long enough, receive buffers fill and frames may be dropped. IEEE 802.3x flow control provides a link-level response for full-duplex Ethernet. A device can send a MAC Control PAUSE frame that asks its directly connected peer to stop transmitting ordinary data frames for a specified interval. The pause is temporary, local to that link, and different from congestion control performed by higher-layer protocols.

Tech 16 Sep 2026 5 min read

DNS Negative Caching Temporarily Stores Name Errors

A DNS cache does not store only successful answers. Recursive resolvers can also retain authoritative responses that say a requested name or record does not exist. This behavior is called negative caching. Negative caching reduces repeated work. If many clients ask for the same absent name, a resolver can answer from its cache instead of sending the same query through the DNS hierarchy each time. The trade-off is temporal. If an administrator adds the missing record while a negative answer is still cached, some clients can continue receiving the cached error until its negative cache lifetime expires.

Software Engineering 16 Sep 2026 6 min read

DNS Negative Caching Can Outlive Record Creation

A recursive DNS resolver can continue returning an earlier absence result after the authoritative zone has gained the requested name. The new record and the cached negative answer are not contradictory: they exist at different points in the resolution path, and the cache remains valid until its negative TTL expires or local policy removes it sooner. This behavior gives DNS absence its own cache lifetime. Publishing a record changes authoritative state, but it does not synchronously invalidate negative entries already stored by recursive resolvers.

Tech 15 Sep 2026 7 min read

TCP Window Scaling Expands Receive Capacity

A TCP connection can have plenty of bandwidth available and still transfer data below the path’s capacity. One limit can come from flow control: the receiver tells the sender how much additional data it is prepared to accept, and the sender must respect that boundary. The original TCP header allocates 16 bits to the advertised receive window. That field can represent at most 65,535 bytes directly. TCP window scaling extends its effective range by negotiating a multiplier during connection setup, making much larger receive windows possible without changing the size of the header field.

Tech 15 Sep 2026 5 min read

TCP Nagle Algorithm Batches Small Writes

Applications can hand TCP data in pieces much smaller than the network’s practical segment size. A terminal session, control protocol, or interactive service might produce only a few bytes at a time. Sending every tiny write immediately can create a stream of packets whose headers are much larger than their payloads. The Nagle algorithm reduces that pattern by limiting how aggressively a TCP sender emits new small segments while earlier data is still awaiting acknowledgment.

Software Engineering 15 Sep 2026 7 min read

TCP Half-Close Separates the Two Stream Directions

A TCP peer can reach end-of-stream on incoming data while its outgoing stream remains usable. The event is directional: a FIN closes one side’s sending direction after previously queued bytes, but it does not require the opposite direction to close at the same instant. That property is easy to hide behind APIs that expose a connection as one object with a single close operation. At the protocol boundary, however, TCP carries two byte streams in opposite directions. A half-close makes the distinction visible and gives application protocols a useful signal: one participant can state that its request body is complete while still accepting a response.

Tech 15 Sep 2026 7 min read

TCP Delayed ACK Reduces Acknowledgment Traffic

TCP Delayed ACK Reduces Acknowledgment Traffic TCP acknowledgments provide essential feedback, but sending a separate ACK for every incoming data segment is not always necessary. A receiver can briefly defer an acknowledgment so that one ACK covers more than one segment. This behavior is known as delayed acknowledgment, or delayed ACK. The mechanism reduces packet processing and reverse-path traffic during steady data transfer. It also introduces a timing tradeoff: if another segment does not arrive soon enough, the receiver eventually has to send the pending ACK on its own.

Tech 15 Sep 2026 7 min read

QUIC Connection IDs Keep Sessions Across Address Changes

A network connection is often associated with addresses and ports. That works well while both endpoints keep the same network attachment, but mobile devices regularly move between Wi-Fi and cellular service, and NAT devices can replace an external UDP port while an application is still active. QUIC provides another identifier for the transport connection: the connection ID. A non-zero-length connection ID lets an endpoint associate incoming QUIC packets with existing connection state even when the packet arrives from a different IP address or UDP port.

Tech 15 Sep 2026 5 min read

Path MTU Discovery Finds the Largest Packet a Route Can Carry

A host can know the maximum transmission unit of its own network interface without knowing the smallest limit farther along a route. Ethernet might accept one packet size while a tunnel, access link, or other intermediate network accepts less. Path MTU Discovery, commonly shortened to PMTUD, lets an endpoint adapt to that route-level limit. The mechanism matters because an IP packet that fits the sender’s local link can still be too large for a later hop.

Tech 15 Sep 2026 6 min read

Happy Eyeballs Races IPv6 and IPv4 Connections

A device on a dual-stack network can often reach the same service over both IPv6 and IPv4. DNS may return AAAA records for IPv6 addresses and A records for IPv4 addresses, leaving the client with several possible routes to the destination. Preferring IPv6 and waiting for a complete failure before trying IPv4 sounds orderly, but it can create a visible pause when the IPv6 path is broken or unusually slow. The reverse ordering can hide IPv6 even when it offers a healthy path. Happy Eyeballs avoids both extremes by giving preferred connection attempts a short head start while allowing another address family to compete soon afterward.

Software Engineering 15 Sep 2026 6 min read

Half-Open TCP Connections Hide Peer Failure Until Traffic Resumes

A TCP socket can remain in the established state on one host after the peer has become unreachable or has lost all connection state. No contradiction exists in that state: TCP endpoints maintain local protocol state, and a silent network failure does not automatically deliver evidence that the peer is gone. This creates a boundary between connection state and peer liveness. An established socket records what the local TCP implementation currently knows about a byte-stream association. It is not a continuously refreshed assertion that the remote process, host, route, and intervening network are all operational.

Software Engineering 15 Sep 2026 8 min read

Expect 100-Continue Defers Request Body Transfer

An HTTP/1.1 client can send request headers containing Expect: 100-continue and hold back the request body while the server evaluates those headers. The server can answer with 100 Continue, allowing body transfer to proceed, or send a final response when it can reject the request without receiving the payload. This splits one request into a metadata decision boundary followed, conditionally, by body transmission. The mechanism matters most when a request body is costly to transmit and the server can make a useful decision from request metadata alone. Authentication failure, an unsupported method, or another header-visible rejection can terminate the exchange before those bytes cross the connection. The same split also creates a timing dependency: a client cannot wait forever for an interim response, and servers and intermediaries must preserve the protocol semantics closely enough for progress.

Tech 15 Sep 2026 6 min read

DNS TTL Controls Cache Reuse

DNS TTL Controls Cache Reuse DNS resolvers avoid repeating the full lookup process for every request by caching resource records. Each cached record set carries a time to live, or TTL, that limits how long the resolver can normally reuse that data before consulting its source again. A longer TTL can reduce query traffic and make repeated lookups faster. A shorter TTL narrows the period in which cached data can remain in use after an authoritative record changes. The value therefore connects DNS performance with the timing of operational changes.

Tech 15 Sep 2026 4 min read

DNS Negative Caching Reuses Name Errors

DNS caches are not limited to successful address lookups. A recursive resolver can also retain an authoritative answer that says a requested name does not exist or that a particular record type has no data. This behavior is called negative caching. It prevents repeated requests for the same missing data from reaching authoritative DNS servers on every lookup. Negative answers cover different cases A DNS response can report that an entire domain name does not exist. The NXDOMAIN response code represents this case.

Tech 15 Sep 2026 7 min read

DNS Negative Caching Keeps Failed Lookups Temporary

A DNS lookup does not always return an address or another requested record. An authoritative server can report that a domain name does not exist, or it can report that the name exists but has no record of the requested type. Recursive resolvers can keep these negative answers in cache for a limited period. That behavior reduces repeated traffic for the same failed lookup and prevents authoritative servers from receiving identical questions on every client attempt.

Tech 15 Sep 2026 7 min read

ARP Neighbor Cache Reuses Local IP-to-MAC Mappings

Sending an IPv4 packet across an Ethernet network requires two different kinds of addresses. The IP layer selects a next-hop IPv4 address, while the Ethernet frame needs a destination MAC address that identifies the next hop on the local link. Address Resolution Protocol (ARP) connects those two layers. A host can ask which MAC address corresponds to a local IPv4 address, receive a reply, and store the resulting mapping. Keeping that result in a neighbor cache avoids broadcasting the same question before every packet.

Tech 14 Sep 2026 6 min read

TCP Keepalive Probes Detect Dead Idle Connections

A TCP connection can remain established even when no application data is moving. That is useful for database sessions, remote shells, messaging links, and other services that may stay quiet for long periods. Silence also creates an awkward case. A peer can lose power, move to another network, or disappear behind a failed path without sending a TCP FIN or RST. The other endpoint may retain an established connection because it has received no packet proving that the path is gone.

Tech 14 Sep 2026 6 min read

TCP Fast Open Sends Data During Connection Setup

A conventional TCP connection separates setup from application traffic. The client sends a SYN, the server replies with SYN-ACK, and the client completes the three-way handshake with an ACK. Application data normally follows after that exchange has established the connection. For short transactions, that setup time can be a meaningful part of the total delay. A request may contain only a few hundred bytes, yet it still waits for a network round trip before the server can receive it through the established connection.

Tech 14 Sep 2026 5 min read

Private Wi-Fi Addresses Limit MAC-Based Tracking

Every Wi-Fi interface needs a link-layer address when it communicates on a local wireless network. This identifier is commonly called a MAC address. Network equipment uses it to distinguish devices while delivering frames within the local network. A fixed hardware MAC address can also act as a persistent identifier. If the same value appears across different places, systems observing Wi-Fi activity can potentially associate those appearances with one device. Modern operating systems reduce that exposure by using private or randomized Wi-Fi addresses instead of presenting the hardware address in many situations.

Tech 14 Sep 2026 6 min read

Encrypted DNS Hides Name Queries From Local Networks

Opening a website usually starts with a name lookup. A device needs an IP address for a domain, so it sends a DNS query to a resolver. Traditional DNS commonly sends those queries without transport encryption, which allows networks along the local path to observe or alter them. Encrypted DNS changes that transport. DNS over HTTPS, often called DoH, carries DNS messages inside HTTPS. DNS over TLS, or DoT, carries them through a dedicated TLS connection. Both approaches protect queries between the client and the selected resolver from straightforward inspection on that path.